CVE-2025-49924: WordPress Wholesale Suite plugin <= 2.2.4.2 - Privilege Escalation vulnerability
Published Oct 22, 2025
·Updated
Incorrect Privilege Assignment vulnerability in Josh Kohlbach Wholesale Suite woocommerce-wholesale-prices allows Privilege Escalation.This issue affects Wholesale Suite: from n/a through <= 2.2.4.2.
Affected Software
2 affected components
Josh Kohlbach Wholesale Suite<=2.2.4.2
WordPress Wholesale Suite plugin<=2.2.4.2
Event History
Oct 22, 2025
CVE Published
via MITRE·02:32 PM
Data Sourced
via MITRE·02:32 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-49924?
CVE-2025-49924 is a high severity vulnerability that allows for privilege escalation.
2
How do I fix CVE-2025-49924?
To fix CVE-2025-49924, you should update the Wholesale Suite to the latest version beyond 2.2.4.2.
3
What versions are affected by CVE-2025-49924?
CVE-2025-49924 affects all versions of Wholesale Suite from n/a through 2.2.4.2.
4
Who is impacted by CVE-2025-49924?
Users of the Josh Kohlbach Wholesale Suite and WordPress Wholesale Suite plugin versions up to 2.2.4.2 are impacted by CVE-2025-49924.
5
What type of vulnerability is CVE-2025-49924?
CVE-2025-49924 is classified as an Incorrect Privilege Assignment vulnerability.